Funding Options

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate Funding Options integration, but it gives an authenticated agent broad access to business financing data without enough built-in scoping or approval guidance.

Install only if you trust Membrane and the Funding Options connection. Before allowing actions that create, update, or delete data, require the agent to show the exact endpoint, method, and request body, and revoke the connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill explicitly instructs use of a generic proxy request mechanism to send arbitrary requests to an external API, but it does not warn that user-supplied data may be transmitted off-platform. In an agent setting, this increases the chance of unintended data exfiltration, especially if the agent forwards sensitive prompts, records, or identifiers through the proxy without clear user awareness or confirmation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal